AI governance needs anthropologists
Part 2 of a 2 part series
Abstract
AI governance is described in the vocabulary of law and engineering, but it rests on assumptions about how people behave: assumptions that vary by culture and population and that routinely go unexamined. Anthropology has spent a century developing the methods for documenting exactly that gap, between what institutions assume and what people actually do. The roles built to manage AI’s risks are being filled by every profession except the one trained to see the assumptions underneath them.
Read Part 1 here: The case for business anthropology.
Over the past two years, companies across every sector have posted AI governance roles in significant volume. Regulatory deadlines are real, reputational exposure is rising, and board-level demand for AI oversight has outpaced most companies’ capacity to deliver it. The urgency driving the wave is real.
The default talent pool is the sensible one: lawyers who understand regulatory risk, compliance officers with backgrounds in enterprise risk management, tech policy professionals fluent in both engineering and law. Each candidate brings genuine capability, but the problem sitting beneath the documentation layer (the one that doesn’t disappear once the policies are written and the audits filed) calls for a different analytic type, not simply more expertise.
In my previous essay, I made the broader argument that every persistent business problem is, underneath its jargon, a problem about people, about how they build trust, assign value, and behave differently than the plan assumes they will. AI governance is where that argument gets its sharpest test, because here the behavioral assumptions aren’t adjacent to the legal and technical work; they are what the legal and technical work is actually about, whether or not the people writing it framed it that way. The discipline built over the past century to study exactly this kind of assumption is anthropology, and it is missing from a hiring wave that doesn’t yet know to look for it.
The category error
AI governance has very little to do with AI and everything to do with the people it touches. Governance frameworks make implicit or explicit assumptions about how users will interact with systems, where risk will materialize in practice, and whether protocols that work in one deployment context will transfer to another. Those assumptions don’t come from legal analysis. They come from ideas about human behavior, and ideas about human behavior are not culturally uniform.
This category error isn’t obvious because the legal and technical dimensions of governance work are demanding and absorb most of the available attention. But the behavioral model underlying any governance framework is always present, even when implicit. Policies governing how users give consent assume something about how consent decisions are made. Risk assessment procedures assume something about what counts as harm and for whom. Audit samples assume something about what is representative. When those assumptions go unexamined, the framework performs governance without actually accounting for the behavior it is supposed to govern.
A framework built on the behavioral norms of one cultural context does not translate universally. Rather, it enforces one set of assumptions while appearing neutral. For companies with cross-border deployments, products reaching diverse user populations, or AI systems embedded in international supply chains, this is a risk problem before it’s anything else.
The empirical case
The empirical evidence for this has been accumulating. Ge and colleagues measured cross-cultural variation in how people want to relate to AI systems, surveying respondents the study grouped as European American, Chinese, and African American, categories that mix one national label with two American ones. The differences were significant and structurally patterned. Chinese respondents placed greater weight on connecting with AI, and were more receptive to systems that could exert influence; European American respondents prioritized control and autonomy. African American respondents reflected aspects of both patterns in ways that confirmed neither model alone was universal. These are systematic differences in what users expect from a human-AI relationship.
Governance frameworks that assume a single model of the user relationship carry measurable exposure when deployed across populations with different expectations. This is a liability question before it becomes an ethics one. (I developed this argument in the context of the current U.S. regulatory landscape more fully in a previous essay.) The point here is narrower: when user behavior diverges from the model a framework assumes, the framework documents what the company intended rather than describing actual risk management.
What anthropologists actually bring
What anthropologists bring is a specific set of analytic methods, four of which map directly onto governance competencies.
Behavior-gap analysis. Anthropologists are trained to document what people actually do, as distinct from what institutions assume they do. Applied to governance, this means auditing the distance between the behavioral model embedded in a policy or system and the behavioral reality of the population it is meant to govern. The gap is not theoretical. Fairness frameworks built on ordinary computer-science habits, abstraction and modular design chief among them, routinely misfire once they meet the social context a system actually operates in, because abstraction strips out the very behavior the framework exists to govern. The anthropologist Diana Forsythe drew the underlying distinction decades ago: what a person values, the account they give of their own conduct, and what a trained observer actually sees are three separate sources of data, not interchangeable ones. Governance documentation is built almost entirely from the first two. Auditing the third is what ethnographic fieldwork was built to do.
Cross-cultural intelligence as structural analysis. Cross-cultural competence usually gets measured as a personal trait, a score that travels with an individual into an unfamiliar room. Governance needs the structural version of it, trained on the system rather than the person: the capacity to see when a system’s own logic rests on assumptions that will not generalize, about authority, privacy, consent, reciprocity, and the line between individual and collective choice. Those assumptions rarely announce themselves in documentation; they travel silently inside frameworks and design decisions. And the gap they open will not close by making individuals more culturally aware, because it lives in the institution and the power relations running through it, not in any one person. Making the assumptions legible is the analytic move anthropologists run by default.
Institutional analysis. The same method that finds behavioral gaps in user populations applies inside the company. Governance teams are themselves institutions, with their own assumptions about what counts as risk, whose input gets sought, and which harms the team is positioned to notice. Anthropology has a lineage for turning the lens this way. Laura Nader’s call to “study up” pushed ethnographers to examine the institutions and professionals who hold power, not only the communities subject to it. Mary Douglas’s insight, as institutional theorists have developed it, is that organizations see the risks their existing categories were built to see and carry a blind spot for the rest. Reading a governance team’s own classification scheme, asking why some risks are easy to name and what that ease conceals, is audit work that goes past documentation review. It means turning the method on the body doing the governing, not only on the governed.
Contextual risk sensing. Legal and technical teams excel at identifying risks that existing frameworks have already named and structured. The harder problem sits earlier, with the risks already legible to the communities living with a system long before those risks acquire a regulatory category. By the time a harm has a framework, it has usually already happened. Getting there first takes sustained proximity to the deployment context, the kind of presence periodic audits cannot provide.
The cost of the gap
The cost of the gap becomes visible at the deployment level. When AI systems built inside one institutional context arrive in another, the embedded assumptions travel with them. Birhane’s analysis of algorithmic injustice documents what this looks like in practice: governance frameworks calibrated to one configuration of individual, community, and institution encounter deployment environments where those calibrations don’t hold. The documentation is compliant, yet the system is not behaving as governed.
Birhane’s case study of AI deployment across Africa supplies the specifics. Systems built in Western markets arrive carrying assumptions about what counts as a user, what consent means, and what infrastructure can be taken for granted, assumptions calibrated to the markets where the systems were designed rather than the ones where they are deployed. The resulting exposure stems from uninspected premises rather than malice, a distinction that matters because uninspected premises are the part of the problem that’s actually preventable.
Yuk Hui’s cosmotechnics framework gives the principle behind Birhane’s case. No technology is a neutral artifact that can be dropped anywhere; each technical tradition carries the values and assumptions of the context that produced it, whether or not the team that built it ever made them explicit. Treating a system as culturally neutral is itself a governance decision, one whose consequences surface only in the deployment environments the documentation never described.
What this means for hiring
What does this competency look like on paper? The markers are specific to institutions, not interfaces. Look for graduate training in institutional ethnography or science and technology studies, fieldwork across more than one regulatory or cultural context, and published or applied work that traces how a rule changed shape between the policy room and the point of use. The most diagnostic interview question follows straight from the behavior-gap idea. Ask the candidate to describe a case where what an institution officially did and what it actually did came apart, and to name which kind of evidence exposed the gap, professed values, self-report, or direct observation. A candidate who answers in those terms has already done the work the role requires.
Structurally, the role works best as an advisory function embedded directly in product or compliance teams, or as a standing research capacity that governance leadership can commission for specific deployment questions. The configuration that doesn’t work is hiring competency into a function without the ability to influence how risk categories are defined. If the role can’t shape framework design, it’s decorative rather than protective.
Before the liability event
The empirical record on cultural and behavioral analysis in AI governance is by now substantial. The deployment failures are documented, and the methods for examining them have existed for decades. What remains open is whether companies recognize the available talent before a liability event forces the recognition. AI governance has matured to the point where its behavioral assumptions are starting to generate consequences; namely, audit failures, deployment mismatches, reputational exposure that legal and technical teams could not predict because they were never trained to see it coming. Anthropology has spent more than a century developing the methods that examine exactly these assumptions, and the companies posting governance roles today are hiring from every adjacent field while overlooking the discipline built to do the work.
Read Part 1 here: The case for business anthropology.
AI disclosure: this essay was produced in editorial collaboration with Claude Sonnet 4.6 and reviewed by Claude Opus 4.8.

